Forum Discussion
mf5
Nimbostratus
Aug 27, 2018APM Kerberos authentication
Hello,
Presently we have webmail using 2F-authentication (AD & OTP)
i want to know whether client side authentication uses kerberos between APM and AD?
Thanks.
Stanislas_Piro2
Cumulonimbus
Aug 28, 2018To complete Kevin’s answer
- AD auth authenticate user with session variables
andsession.logon.last.usernamesession.logon.last.password - AD Query request user attributes with LDAP filter
except if you customize the filter in VPE AD Query box.sAMAccountName=${session.logon.last.username}
You can provision these variables with
- logon pages
- 401 response pages
- variable assign box
- irules
When working with clientside Kerberos, ntlm, saml or oauth, the password variable is not provisionned because it is not received by APM.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects
